| UAC Bypass Attempt via Windows Directory Masquerading | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Privilege Escalation via InstallerFileTakeOver | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential CVE-2025-33053 Exploitation | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Execution from Unusual Directory - Command Line | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Signed Proxy Execution via MS Work Folders | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Unusual Network Activity from a Windows System Binary | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Masquerading as System32 DLL | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Windows Error Manager Masquerading | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Program Files Directory Masquerading | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Masquerading as Communication Apps | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Masquerading as Business App Installer | Low | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Masquerading as Svchost | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious Endpoint Security Parent Process | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Execution via Windows Command Debugging Utility | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Process Execution from an Unusual Directory | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious Microsoft Antimalware Service Execution | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious Communication App Child Process | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Microsoft Office Sandbox Evasion | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious File Creation via Kworker | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Process Started from Process ID (PID) File | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Abnormal Process ID or Lock File Created | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Process Name Stomping with Prctl | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Executable Masquerading as Kernel Process | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Directory Creation in /bin directory | Low | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| System Path File Creation and Execution Detected via Defend for Containers | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |